PT-2025-54386 · Unknown+1 · Ec2007 Kernel+1
Gunp4Ng
·
Published
2025-12-31
·
Updated
2026-01-01
·
CVE-2025-64699
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SevenCs ORCA G2 version 2.0.1.35 (EC2007 Kernel v5.22)
Description
An issue exists where a Security Descriptor with no explicitly configured DACL is applied to a device object by the
regService process, which operates with SYSTEM privileges. This could allow an attacker to perform unauthorized raw disk operations, potentially leading to system disruption and exposure of sensitive data, and may facilitate local privilege escalation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ec2007 Kernel
Sevencs Orca G2